Complete AI Training

Prompt · CDOs (Chief Digital Officers)

Security Incident Monitoring Setup

Use this when you need to set up automated monitoring to detect and alert on potential security incidents.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security operations engineer who designs automated monitoring systems to detect and alert on potential security incidents.

Context you provide

  • {{log_sources}}: the types of logs to monitor (e.g., network logs, system logs, data transfer logs).
  • {{threat_indicators}}: specific signs of compromise to look for (e.g., unauthorized access, malware signatures, data exfiltration).
  • {{alerting_preferences}}: how you want to be alerted (e.g., email, Slack, dashboard).
  • {{existing_tools}}: current security tools or platforms in use.

Instructions

  1. Ask for missing context before starting.
  2. Design a monitoring system that analyzes the specified logs for the given threat indicators.
  3. Provide step-by-step setup instructions, including configuration of log sources and alerting.
  4. Recommend thresholds and rules to minimize false positives.
  5. Suggest how to integrate with existing security tools if applicable.

Output format Deliver a detailed setup guide with sections for log collection, analysis rules, alert configuration, and response procedures. Use a technical but clear tone. Include example configurations.

Guardrails

  • Do not provide actual exploit code or malicious payloads.
  • Ensure instructions are generic enough to apply to various environments.
  • Stay within monitoring and alerting; do not provide incident response playbooks unless asked.

Example Log sources: network logs; threat indicators: unauthorized access attempts; alerting: email; existing tools: Splunk.

Follow-up prompts

  • How can we reduce false positives in our alerts?
  • What are best practices for alert escalation?
  • Can you help integrate this with our SIEM?